Updated News Around the World

Cowin: Cowin website is completely safe, says health ministry; IT minister tweets in support – Times of India

The health ministry has denied reports of data breach of Cowin website that has appeared on some social media platforms. These reports allege breach of data from the Cowin portal of the union health ministry, which is a repository of all data of beneficiaries who have been vaccinated against Covid19. Cowin was developed and is owned and managed by the ministry of health and family welfare.Certain posts on the social media platform Twitter claimed that using a Telegram (online messenger application) Bot, the personal data of individuals who have been vaccinated can be accessed. It is reported that the Bot has been able to pull individual data by simply passing the mobile number or Aadhaar number of a beneficiary.
The ministry clarified that all such reports are without any basis and mischievous in nature. Cowin portal of the health ministry is completely safe with adequate safeguards for data privacy. Furthermore, security measures are in place on the Cowin portal, with web application firewall, anti-DDoS, SSL/TLS, regular vulnerability assessment, identity & access management etc. Only OTP authentication-based access of data is provided. It further said that all steps have been taken and are being taken to ensure security of the data in the Cowin portal.
IT minister Rajeev Chandrasekhar too denied the suspected data hack. In a tweet, pointed out 4 things to support his statement. “With ref to some Alleged Cowin data breaches reported on social media, @IndianCERT has immdtly responded n reviewed this
✅A Telegram Bot was throwing up Cowin app details upon entry of phone numbers
✅The data being accessed by bot from a threat actor database, which seems to hv been populated wth previously stolen data stolen in the past.
✅It does not appear that Cowin app or database has been directly breached
✅National Data Governance policy has been finalized that will create a common framework of Data storage, Access and Security standards across all of govt.”
Presently, Cowin data access is available at three levels:
* Beneficiary dashboard: The person who has been vaccinated can have an access to the Cowin data through use of registered mobile number with OTP authentication.
* Cowin authorized user: The vaccinator with use of authentic login credential provided can access personal level data of vaccinated beneficiaries. But the Cowin system tracks and keeps record of each time an authorised user accesses the Cowin system.
* API-based access: The third party applications who have been provided authorised access of Co-WIN APIs can access personal level data of vaccinated beneficiaries only through beneficiary OTP authentication.

Health ministry asks CERT-In to review security
The Union Health Ministry has requested India’s nodal cybersecurity agency — Computer Emergency Response Team (CERT-In) — to look into the alleged security breach and submit a report. In addition, an internal exercise has been initiated to review the existing security measures of Cowin. CERT-In in its initial report has pointed out that the backend database for Telegram bot was not directly accessing the APIs of the CoWIN database.

function loadGtagEvents(isGoogleCampaignActive) { if (!isGoogleCampaignActive) { return; } var id = document.getElementById('toi-plus-google-campaign'); if (id) { return; } (function(f, b, e, v, n, t, s) { t = b.createElement(e); t.async = !0; t.defer = !0; t.src = v; t.id = 'toi-plus-google-campaign'; s = b.getElementsByTagName(e)[0]; s.parentNode.insertBefore(t, s); })(f, b, e, 'https://www.googletagmanager.com/gtag/js?id=AW-877820074', n, t, s); };

window.TimesApps = window.TimesApps || {}; var TimesApps = window.TimesApps; TimesApps.toiPlusEvents = function(config) { var isConfigAvailable = "toiplus_site_settings" in f && "isFBCampaignActive" in f.toiplus_site_settings && "isGoogleCampaignActive" in f.toiplus_site_settings; var isPrimeUser = window.isPrime; if (isConfigAvailable && !isPrimeUser) { loadGtagEvents(f.toiplus_site_settings.isGoogleCampaignActive); loadFBEvents(f.toiplus_site_settings.isFBCampaignActive); } else { var JarvisUrl="https://jarvis.indiatimes.com/v1/feeds/toi_plus/site_settings/643526e21443833f0c454615?db_env=published"; window.getFromClient(JarvisUrl, function(config){ if (config) { loadGtagEvents(config?.isGoogleCampaignActive); loadFBEvents(config?.isFBCampaignActive); } }) } }; })( window, document, 'script', );

For all the latest Technology News Click Here 

 For the latest news and updates, follow us on Google News

Read original article here

Denial of responsibility! NewsUpdate is an automatic aggregator around the global media. All the content are available free on Internet. We have just arranged it in one platform for educational purpose only. In each content, the hyperlink to the primary source is specified. All trademarks belong to their rightful owners, all materials to their authors. If you are the owner of the content and do not want us to publish your materials on our website, please contact us by email – [email protected]. The content will be deleted within 24 hours.